tcpdump mailing list archives
RE : RE : capturing and injection on same interface
From: "Jacky Buyck" <jacky.buyck () wanadoo fr>
Date: Fri, 9 Jan 2004 14:59:51 +0100
Ok I see. But I still thinking that it can be more simple to use 2 interfaces. MITM be more simple if a make a real cut between your two system. But that is true that my vision is more oriented in a test lab way so ... -----Message d'origine----- De : Alberto Ornaghi [mailto:alor () antifork org] Envoyé : vendredi 9 janvier 2004 14:27 À : Jacky Buyck; tcpdump-workers () tcpdump org Objet : Re: RE : [tcpdump-workers] capturing and injection on same interface Jacky Buyck wrote:
Hmmmm ... The better can be simply to use a second interface. What is the utility to modify and reinject a packet on the same link than the good one : the receiver will always received the good packet first ignoring your modified one. No ???
in a mitm attack the victim will not receive the packet until you forwardi it...
Except if you've a real need for this.
think about a bridge in userland. since it has to be bidirectional, what
you inject on one iface will be recaptured back as it was received from
that interface...
bye
--
--==> ALoR <==---------------------- - - -
There are only 10 types of people in this world...
Those who understand binary, and those who don't.
-
This is the TCPDUMP workers list. It is archived at
http://www.tcpdump.org/lists/workers/index.html
To unsubscribe use mailto:tcpdump-workers-request () tcpdump org?body=unsubscribe
Current thread:
- RE : RE : capturing and injection on same interface Jacky Buyck (Jan 09)
